Security fixes are provided for the latest released minor version of Agent VCR.
Please report security issues privately by emailing the maintainer listed in
pyproject.toml, or by opening a private GitHub security advisory if available.
Do not open a public issue for vulnerabilities involving:
- token, prompt, or secret exposure in VCR recordings
- unsafe filesystem rollback behavior
- dashboard/API access control bypasses
- package publishing or supply-chain compromise
Include the affected version, reproduction steps, impact, and any suggested fix. You should receive an initial response within 7 days.